Forum Discussion

JoanneMcG's avatar
JoanneMcG
Trusted Cover User
12 months ago

No security in Myob today

Hello Myob - why is there no security in Myob today????

All our staff were able to open file without having to log in - I also didn't need to log into this Forum

This is not acceptable Myob - why bother with 2FA when there is absolutely no security needed to get into the file today?

When will you fix this terrible issue?

  • I have come in this morning and this is how it went:

    Open Myob, click to log in and I am automatically taken to the screen showing the active file - I was not required to log in, provide a password let alone any 2FA.  I also came to this forum page.  Again, I clicked to log in and I was immediately brought to this site without any login required.

    The normal way to log in, even if 'tick for 30 days' was ticked, is to use email address and password - these two key steps were not there, it was straight into the file (and forum site).   Considering that I logged out of the company file prior to leaving work yesterday means that there is something wrong with the file.

    This is not normal nor acceptable.  It pretty much implies that there is no security in our company file.

    I need Myob to look into this as a matter of urgency.

     

    Update:  so pretty much over this whole issue, don't worry about Myob, we will look for a new solution to our accounting needs.

     

  • WilMyob43's avatar
    WilMyob43
    Contributing User

    Exactly the same happened to me.  I am feeling very anxious.  We had a security breach four months ago and I thought the 2FA would be more trustworthy.  I don't know if it is safe to still use it today?  

     

    Please reset and update your password.  I would like some answers from MYOB about this situation and why this happened.  What are the protocols for this?  

  • JoanneMcG's avatar
    JoanneMcG
    Trusted Cover User

    Myob people - its been many hours now, no one has responded as yet!

    What is the state of security in my file? is there any security in place?

    If we now get compromised are Myob going to pay for the defect stemming from their system?

    I need an answer!

    • WilMyob43's avatar
      WilMyob43
      Contributing User

      Still no response from Myob about this morning.

       

      I recently closed out of Myob and reset my password to a new password.

       

      However, I logged out and went back in and was able to access to the company file straight away without asking me to enter password or 2FA Authenticator. I don't think I am fully secure and protected right now.  Can I please get some answer soon as possible.

       

       

  • Isaiah_C's avatar
    Isaiah_C
    MYOB Moderator

    Hi All,

     

    Thank you for your posts and for letting us know your concern. I'm sorry to hear that you feel your account is not secured. I'll be more than happy to help you with this. I want to know if it's an online or offline file.

     

    • The AccountRight Live login: This is your my.myob account details (your email address and password). If you're signed in, you will not be prompted for this log-in (email address and password), and you're automatically signed into the company file once you select it.
    • The company file login: this is your User ID and password. If you've linked your user ID to your my.myob account through Setup >> User Access, this would skip the User ID and password screen. To make sure you are totally signed out, you need to go to Services>>Sign out of AccountRight Live. This will close the file, and once you select the company file again, it will ask for your email address, password, and 2FA code. If it's the company file sign on, then you'll need to check the set-up of your user ID.

     

     

    Please let me know if you need further help.

     

    Kind regards,

    Sai

    • JoanneMcG's avatar
      JoanneMcG
      Trusted Cover User

      I think you are missing the point - 2FA is in place in our company file, no access was updated or amended - it was simply a case of during the opening of the file this morning there was no 2FA in place.  This is a Myob issue, not a user issue.

      If nothing was changed in our company file (I was last to use on Friday, and first to use this morning) how can the 2FA not be working.  That is the question Myob needs to answer.

      Also, I have come home from work to work in Myob - again I didn't need any authentication to get into the file.

      As stated, to "log in" to the forum this morning no 2FA was required either.

      Why?  Where is our security Myob?  How can this happen to me, and other unrelated Myob users (those that put posts up)?

      • Isaiah_C's avatar
        Isaiah_C
        MYOB Moderator

        Hi JoanneMcG,

         

        Thank you for the response. In this case, the reason you are not being asked to put the 2FA because you tick the box that says, 'Trust this device for 30 days'. You don't need to enter the code once you tick that box. You can clear the 'Trust this device' setting by signing out to AccountRight (Service>>Sign out from AccountRight).  Trust this device for 30 days, has detailed information and instructions to assist you with this.

         

         

        Please let me know if you need further help.

         

        Kind regards,

        Sai